Infographic

Security checks across malware telemetry and agentic risk

Overview

The skill's files, runtime instructions, and required credential line up with an image-generation/infographic tool that calls the WeryAI gateway; nothing in the bundle appears to be doing unrelated or hidden exfiltration.

This package appears coherent for its stated purpose (building prompts and driving an image-generation gateway). Before installing or running setup/bootstrap: 1) Confirm you trust the WeryAI gateway (https://api.weryai.com) and are willing to provide IMAGE_GEN_API_KEY. 2) Inspect vendor scripts if you want to review network calls (submit-image/submit-text client code is included). 3) Expect npm install to run across multiple package.json files if you run scripts/bootstrap or setup — consider running in an isolated environment or with --dry-run first. 4) Be aware the tool will write local config under .image-skills/ and output images to project directories; if you don't want persistent changes, avoid running setup that persists the API key or creating the scaffold. If you want extra assurance, run the tool in a sandbox or review the vendor client code in scripts/vendor/weryai-core and scripts/vendor/weryai-image before providing credentials.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal